Technology Risk & Security Manager (SCAR)
Offer summary

(Summary generated by AI based on the full job description)

The project focuses on managing the Technology Demand Intake process and risk assessment for new technologies, platforms, SaaS, PaaS, SAP services, and AI-enabled solutions. Key qualifications include experience in technology risk management, cybersecurity, compliance, and IT architecture within a global environment and knowledge of standards like ISO 27001, SOC 2, ITIL. Responsibilities cover risk evaluation, executive reporting, cross-department collaboration, vendor and audit support, and continuous governance process improvement.

newyou can start ASAP

Technology Risk & Security Manager (SCAR)

Company: Simon-Kucher Core Business Services Sp. z o. o.

from: 25 August 2026
to: 24 September 2026
28 000 - 30 000gross/ mth.contract of employment (full-time)
Salary details

The compensation package at Simon-Kucher CBS consists of: a gross base salary, a remote work allowance paid monthly and an annual bonus. The bonus is paid in December and is based on the results of a 360-degree performance evaluation.

basic salary
fixed bonus (e.g., quarterly, annual)
Offer parameters
level:senior
working mode:remote • hybrid
Warszawa, Mokotów
Warszawa, MokotówDomaniewska 42View on map

Requirements

Operating system

Windows

Our requirements

  • Experience in a complex global environment, comparable consulting or service industries is preferred.
  • Bachelor’s Degree required – preferred in the area of Technology, MIS, Cybersecurity, etc.
  • 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.
  • Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI-enabled technologies.
  • Experience assessing SaaS, cloud, third-party, and AI-enabled solutions, with the ability to identify risks, mitigation strategies, and implementation requirements.
  • Experience improving governance processes, workflows, standards, and risk management practices.
  • Knowledge of security and governance frameworks such as ISO 27001, SOC 2, ITIL, or similar.
  • Experience with security controls, risk assessments, compliance, audit support, and governance approval processes.
  • Ability to evaluate platform architecture, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational security.
  • Understanding of enterprise architecture, cloud security, vendor risk management, and secure technology implementation.
  • Strong stakeholder management skills with experience working across IT, Security, Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business teams.
  • Experience preparing executive-level presentations, risk reports, and decision-ready documentation, and presenting recommendations to senior leadership.
  • Experience evaluating third-party vendors, cloud platforms, SaaS solutions, and managed services within global IT environments.
  • Experience supporting technology onboarding, vendor risk assessments, procurement, RFPs, and cross-functional technology initiatives.
  • Ability to manage risks, remediation activities, project dependencies, and implementation progress across the technology lifecycle.
  • CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent certification (or comparable hands-on experience).

Your responsibilities

  • Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive-facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities and tight timelines.

About the project

This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating within the company’s Technology Demand Intake Process, which is closely connected to implementation and lifecycle governance. This individual will focus on reviewing technical concepts, stand-alone products, services, and AI-enabled solutions that the company plans to implement or integrate into its complex global enterprise technology landscape, including SaaS, PaaS, SAP, and AI-enabled platforms. You will be responsible for assessing and governing new technology demands, services, platforms, and AI-enabled solutions through the organization’s technology intake process. The role ensures that security, compliance, architecture, operational, and business risks are identified, clearly documented, and addressed through effective and practical mitigation measures.

This is how we organize our work

This is how we work

in house

Please remember to submit your application in English.

Other applications will not be considered. The candidate should have an EU work permit, we do not offer visa for this position.
Company

What we offer

  • A stable employment contract (please note that we do not offer B2B contracts).
  • Private medical insurance in the highest package fully paid by the employer (VIP Allianz).
  • Multisport card fully financed by the employer.
  • Annual bonus (dependent on the evaluation).
  • Employee referral program.
  • Remote work subsidy of €500 to start, then monthly bonus for utilities.
  • International Travel Safety card.
  • Access to LinkedIn Learning and Headspace.
  • Employee Assistance Program (EAP).
  • Microsoft Workplace Discount Program.
  • Access to an online platform offering exclusive discounts and special offers from well-known brands.
  • Birthday book for the employee.
  • Internal Learning&Development Department with more than 5 000 different training courses.
  • Our office is pet-friendly, so feel free to bring your furry friend to work and enjoy their company throughout the day!
  • Extended Business Travel Option - opportunity to extend your business trips and stay a little longer to explore some of Europe’s most exciting cities.

Benefits

  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of professional training & courses
  • remote work opportunities
  • flexible working time
  • integration events
  • mobile phone available for private use
  • computer available for private use
  • extra social benefits
  • sharing the costs of tickets to the movies, theater
  • holiday funds
  • employee referral program

Recruitment stages

  • 1.
    Meeting with Recruiter
  • 2.
    Meeting with a Supervisor
  • 3.
    Meeting with the Team

Simon-Kucher Core Business Services Sp. z o. o.

Simon-Kucher Core Business Services is one of international Simon-Kucher brand Office located in Warsaw. As a Shared Services Center, we provide end-to-end operational support to more than 42 Simon-Kucher offices globally, combining local expertise with international scope.
Established in Warsaw in 2023, our hub has been growing dynamically and currently employs over 100 professionals across HR, Finance, IT, Marketing, Data & AI, Legal, Market Research and Engine teams. By supporting a globally recognized consulting organization with a strong market position, we play a key role in enabling efficiency, scalability, and continued success. We foster a culture built on innovation, knowledge sharing, and continuous learning, making it an inspiring place for ambitious talent to grow and thrive.
Join us and be part of shaping the future of a fast-growing global center of excellence.

This is how we work

Technology Risk & Security Manager (SCAR)
28k–30k zł / mth. (CoE)
I apply to:
Simon-Kucher Core Business Services Sp. z o. o.
Warszawa, Mokotów
Pracodawca zbiera zgłoszenia przez swój system.
Przejdziesz na zewnętrzny formularz.

By clicking "Aplikuj" you confirm that you've read and accepted our Terms and Conditions.



This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer